Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
2019-06-17T20:15:09.540
2024-11-21T03:57:25.380
Modified
CVSSv3.0: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | concretecms | concrete_cms | 8.4.3 | Yes |